Dlink Dir-859 Firmware vulnerabilities
8 known vulnerabilities affecting dlink/dir-859_firmware.
Total CVEs
8
CISA KEV
2
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2024-0769CRITICALCVSS 9.8KEVv1.062024-01-21
CVE-2024-0769 [MEDIUM] CWE-22 CVE-2024-0769: ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rat
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to
nvd
CVE-2023-36092CRITICALCVSS 9.8v1.05b032023-07-31
CVE-2023-36092 [CRITICAL] CWE-863 CVE-2023-36092: Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escal
Authentication Bypass vulnerability in D-Link DIR-859 FW105b03 allows remote attackers to gain escalated privileges via via phpcgi_main. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
nvd
CVE-2022-25106MEDIUMCVSS 5.5v1.052022-03-04
CVE-2022-25106 [MEDIUM] CWE-787 CVE-2022-25106: D-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacg
D-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload.
nvd
CVE-2019-20217CRITICALCVSS 9.8v1.05v1.06b012020-01-29
CVE-2019-20217 [CRITICAL] CWE-78 CVE-2019-20217: D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS comman
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because SERVER_ID is mishandled. The value of the urn: service/device is checked with the strstr function, which allows an attacker to concatenate arbitrary commands separated by
nvd
CVE-2019-20216CRITICALCVSS 9.8v1.05v1.06b012020-01-29
CVE-2019-20216 [CRITICAL] CWE-78 CVE-2019-20216: D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS comman
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via the urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because REMOTE_PORT is mishandled. The value of the urn: service/device is checked with the strstr function, which allows an attacker to concatenate arbitrary commands separated b
nvd
CVE-2019-20215CRITICALCVSS 9.8PoCv1.05v1.06b012020-01-29
CVE-2019-20215 [CRITICAL] CWE-78 CVE-2019-20215: D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS comman
D-Link DIR-859 1.05 and 1.06B01 Beta01 devices allow remote attackers to execute arbitrary OS commands via a urn: to the M-SEARCH method in ssdpcgi() in /htdocs/cgibin, because HTTP_ST is mishandled. The value of the urn: service/device is checked with the strstr function, which allows an attacker to concatenate arbitrary commands separated by shel
nvd
CVE-2019-20213HIGHCVSS 7.5≤ 1.05b03v1.06b012020-01-02
CVE-2019-20213 [HIGH] CWE-74 CVE-2019-20213: D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUT
D-Link DIR-859 routers before v1.07b03_beta allow Unauthenticated Information Disclosure via the AUTHORIZED_GROUP=1%0a value, as demonstrated by vpnconfig.php.
nvd
CVE-2019-17621CRITICALCVSS 9.8KEV≤ 1.05b03v1.06b012019-12-30
CVE-2019-17621 [CRITICAL] CWE-78 CVE-2019-17621: The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
nvd